Dallas Fed: AI and bank cybersecurity
Dallas Fed says generative AI and AI agents belong inside existing bank risk frameworks.
The Federal Reserve Bank of Dallas said U.S. federal banking agencies oversee generative and agentic AI models through broad risk frameworks that apply to cybersecurity, fraud and digital assets. The Federal Reserve Board also published updated resources on September 2 to manage the risks and opportunities of frontier AI within existing supervisory structures.
The Federal Reserve Bank of Dallas said U.S. federal banking agencies, including the Federal Reserve, the OCC and the FDIC, oversee generative and agentic AI models through broad, principle-based frameworks. That approach extends to cybersecurity management at supervised financial institutions, including those exposed to digital assets and fraud, and draws on updated resources the Federal Reserve Board published on September 2, 2026.
What changed with Federal Reserve guidance?
The Federal Reserve Board published updated resources to help financial institutions manage the cybersecurity risks and opportunities of frontier AI. The material fits within existing supervisory frameworks and, according to analysis cited by the Federal Reserve Bank of Dallas and BankingNewsAI, there were no bank-specific rules aimed at AI agents as such as of September 2026.
In practice, that means AI models must be folded into existing operational risk, cybersecurity and third-party governance frameworks. The regulatory reading is that AI security is not treated as a separate model-risk regime, but as part of the classic domains of information security and vendor control.
What do the existing U.S. frameworks require?
The main reference frameworks in the United States already call for concrete controls such as strong authentication, encryption, technical testing and third-party management. In the case of the FFIEC, information security guidance sets interagency standards for supervised institutions and also reaches outside technology and service providers that support them.
The FFIEC guidance requires ongoing IT and cybersecurity risk assessments, along with supervision of the vendor security program. It also states that deficiencies can lead to formal findings, Matters Requiring Attention and enforcement actions or civil penalties through the examination process used by member agencies.
The FTC Safeguards Rule follows the same line for nonbank financial institutions under the agency’s jurisdiction. It requires a written information security program overseen by a qualified individual, based on a documented risk assessment and built around encryption, multifactor authentication, incident response and vendor oversight.
What about New York and critical third parties?
The NYDFS rule 23 NYCRR 500 requires covered entities to maintain a risk-based cybersecurity program with specific technical controls and regulator reporting. The rule applies to banks, insurers, mortgage lenders and other financial firms authorized or licensed in New York, regardless of their country of origin.
That framework includes multifactor authentication, encryption of nonpublic information, privilege management and vulnerability management. It also requires notification of cybersecurity events that meet certain criteria, generally within 72 hours, reporting of ransomware payments and an annual compliance certification signed by a senior officer.
The amended text in effect since November 2023 adds a precise cadence for testing and risk assessment. Regulated entities must conduct internal and external penetration testing at least once a year, using qualified internal or external personnel, and supplement that with automated vulnerability scans based on risk assessment and after material system changes. The risk assessment itself must be updated at least once a year and after any material change.
How does this affect banks and fintechs in Latin America?
The U.S. supervisory logic also reaches Latin American banks and fintechs that operate in the United States or rely on technology vendors for onboarding, fraud prevention or data management. According to Uptiq, the regulatory narrative places AI security inside the classic domains of information security and third-party risk, so AI tools must meet the same access, logging, monitoring and data protection controls as other critical systems.
The focus on vendors is especially sensitive in identity verification workflows. Commerce Security Authority noted that the FFIEC requires firms to assess how the provider handles, stores and disposes of sensitive personal information, and points to the Outsourcing Technology Services booklet for detailed expectations around IDV platforms.
That has direct implications for fintechs and banks that outsource digital onboarding, even when the provider is outside the United States. Analyses of large incidents involving identity verification vendors argue that due diligence and third-party oversight must examine how data such as driver’s licenses and official documents are protected.
That is reinforced by the Financial Stability Board’s signal to the G20 in August 2026, which classified frontier AI as a structural risk vector for global financial stability. According to the cited analysis, that view increases the likelihood that supervisors such as the Federal Reserve will include AI-powered cyberattack scenarios in operational risk reviews for banks with international exposure, including subsidiaries in Latin America.
Sources
- FFIEC Information Security Guidance for Banksvibgrate.com· Vibgrate
- What Is AI Security in Financial Services?uptiq.ai· Uptiq
- NYDFS 23 NYCRR 500: NY Financial Cybersecurity Rulevibgrate.com· Vibgrate
- 153M Licenses Breached: IDV Vendor Audit Gaps Exposedcommercesecurity.org· Commerce Security Authority
- FTC Safeguards Rule (GLBA): Financial Data Securityvibgrate.com· Vibgrate
- What Regulators Say About AI Agents in Banking (2026): Every Position, Datedbankingnewsai.com· BankingNewsAI
- Securing digital financial assets from AI-driven frauddallasfed.org· Federal Reserve Bank of Dallas
- 23 NYCRR Part 500, Cybersecurity Requirements for Financial Services Companies, Second Amendment Textdfs.ny.gov· New York State Department of Financial Services
- Federal Banking Agencies Coordinate Handling of Highly Sensitive Examination Informationbonadio.com· Bonadio & Co.
- Letter from the FSB Chair to G20 Finance Ministers and Central Bank Governors (August 2026)fsb.org· Financial Stability Board
- How Often Should You Do Penetration Testing? (2026)stingrai.io· Stingrai



